Kafka UI经oauth2-proxy接入Auth0未触发认证的问题排查求助
我们正尝试在Kubernetes集群中部署Kafka UI应用,通过oauth2-proxy接入Auth0作为身份提供商(IDP),但部署完成后可直接访问网站进入Kafka UI门户,未触发认证流程。
以下是使用的Kafka UI清单:
apiVersion: apps/v1 kind: Deployment metadata: name: kafka-ui-deployment labels: app: kafka-ui spec: replicas: 1 selector: matchLabels: app: kafka-ui template: metadata: labels: app: kafka-ui spec: containers: - name: kafka-ui image: provectuslabs/kafka-ui:latest env: - name: KAFKA_CLUSTERS_0_NAME value: "kafka-cluster" - name: KAFKA_CLUSTERS_0_BOOTSTRAPSERVERS value: "10.6.0.0:9094" - name: KAFKA_CLUSTERS_0_PROPERTIES_SECURITY_PROTOCOL value: "SASL_PLAINTEXT" - name: KAFKA_CLUSTERS_0_PROPERTIES_SASL_MECHANISM value: "SCRAM-SHA-512" - name: KAFKA_CLUSTERS_0_PROPERTIES_SASL_JAAS_CONFIG value: 'org.apache.kafka.common.security.scram.ScramLoginModule required username="kafka-username" password="kafka-password";' imagePullPolicy: Always resources: requests: memory: "1Gi" cpu: "250m" limits: memory: "2Gi" cpu: "1" ports: - containerPort: 8080 --- apiVersion: v1 kind: Service metadata: name: kafka-ui-service labels: app: kafka-ui spec: selector: app: kafka-ui type: LoadBalancer ports: - port: 80 targetPort: 8080 --- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: kafkaui-ingress annotations: haproxy.ingress.kubernetes.io/ssl-redirect: "true" haproxy.ingress.kubernetes.io/service-upstream: "true" # cert-manager.io/issuer: letsencrypt # cert-manager.io/issuer-kind: ClusterIssuer external-dns.alpha.kubernetes.io/hostname: mydomain.ca external-dns.alpha.kubernetes.io/ttl: "120" external-dns.alpha.kubernetes.io/target: "my-public-ip" external-dns.alpha.kubernetes.io/cloudflare-proxied: "true" haproxy.ingress.kubernetes.io/auth-url: "http://kafka-ui-oauth2-proxy.default.svc.cluster.local:4180/oauth2/auth" haproxy.ingress.kubernetes.io/auth-signin: "http://kafka-ui-oauth2-proxy.default.svc.cluster.local:4180/oauth2/start?rd=http://kafka-ui-oauth2-proxy.default.svc.cluster.local:4180/oauth2/callback" haproxy.ingress.kubernetes.io/auth-response-headers: "X-Auth-Request-Email:email,X-Auth-Request-User:user,authorization" labels: app: kafkaui-ingress spec: ingressClassName: haproxy rules: - host: mydomain.ca http: paths: - path: / pathType: Prefix backend: service: name: kafka-ui-service port: number: 80 tls: - hosts: - mydomain.ca secretName: kafkaui-ingress
oauth2-proxy清单:
apiVersion: apps/v1 kind: Deployment metadata: labels: k8s-app: kafka-ui-oauth2-proxy name: kafka-ui-oauth2-proxy spec: replicas: 1 selector: matchLabels: k8s-app: kafka-ui-oauth2-proxy template: metadata: labels: k8s-app: kafka-ui-oauth2-proxy spec: containers: - args: - --provider=oidc - --oidc-issuer-url=https://my-auth0-domain.com/ # replace with your OIDC IdP's issuer url - --scope=openid profile email - --email-domain=* - --upstream=http://kafka-ui-service.default.svc.cluster.local:80 - --pass-authorization-header=true - --set-authorization-header=true - --pass-access-token=true - --reverse-proxy=true - --cookie-refresh=1h - --cookie-expire=24h - --cookie-samesite=lax - --skip-provider-button=true - --skip-oidc-discovery=true - --oidc-jwks-url=https://my-auth0-domain.com/.well-known/jwks.json - --set-xauthrequest=true - --redirect-url=https://mydomain.ca/oauth2/callback env: - name: OAUTH2_PROXY_HTTP_ADDRESS value: "0.0.0.0:4180" - name: OAUTH2_PROXY_CLIENT_ID value: "client-id" - name: OAUTH2_PROXY_CLIENT_SECRET value: "client-secret" - name: OAUTH2_PROXY_COOKIE_SECRET value: "cookie-secret" - name: OAUTH2_PROXY_LOGIN_URL value: "https://my-auth0-domain.com/authorize" - name: OAUTH2_PROXY_REDEEM_URL value: "https://my-auth0-domain.com/oauth/token" - name: OAUTH2_PROXY_VALIDATE_URL value: "https://my-auth0-domain.com/userinfo" - name: OAUTH2_PROXY_PROFILE_URL value: "https://my-auth0-domain.com/userinfo" - name: OAUTH2_PROXY_OIDC_EXTRA_AUDIENCES value: "https://mydomain.ca" image: quay.io/oauth2-proxy/oauth2-proxy:latest imagePullPolicy: Always name: oauth2-proxy ports: - containerPort: 4180 protocol: TCP resources: limits: cpu: 100m memory: 128Mi requests: cpu: 100m memory: 128Mi --- apiVersion: v1 kind: Service metadata: labels: k8s-app: kafka-ui-oauth2-proxy name: kafka-ui-oauth2-proxy spec: ports: - name: http port: 4180 protocol: TCP targetPort: 4180 selector: k8s-app: kafka-ui-oauth2-proxy --- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: kafka-ui-oauth2-proxy annotations: haproxy.org/rate-limit-requests: "1000" # Required: The limit haproxy.org/rate-limit-period: "1s" # Recommended: The window haproxy.org/rate-limit-status-code: "429" # Your desired status code haproxy.ingress.kubernetes.io/proxy-body-size: "2000m" spec: ingressClassName: haproxy rules: - host: "mydomain.ca" # change to your domain http: paths: - path: /oauth2 pathType: Prefix backend: service: name: kafka-ui-oauth2-proxy port: number: 4180
Auth0控制台配置:
Application Login URIs: https://mydomain.ca/oauth2/start Allowed Callback URLs: https://mydomain.ca/oauth2/callback Allowed Logout URLs: https://mydomain.ca Allowed Web Origins: https://mydomain.ca
该应用已启用RBAC,关联了标识符/受众为https://mydomain.ca的API,并在授权门户创建安全组分配角色权限。
1. 修正Ingress的Auth-Signin地址
当前kafkaui-ingress的auth-signin使用集群内部Service地址,外部浏览器无法访问该地址,导致认证跳转失效,Ingress可能直接放行请求。需改为外部域名地址:
haproxy.ingress.kubernetes.io/auth-signin: "https://mydomain.ca/oauth2/start?rd=https://mydomain.ca/oauth2/callback"
2. 修改Kafka UI Service类型为ClusterIP
当前Kafka UI Service是LoadBalancer类型,会直接暴露外部IP,用户可能绕过Ingress直接访问该IP,从而跳过认证。将Service改为ClusterIP,强制流量经过Ingress:
apiVersion: v1 kind: Service metadata: name: kafka-ui-service labels: app: kafka-ui spec: selector: app: kafka-ui type: ClusterIP ports: - port: 80 targetPort: 8080
3. 校验oauth2-proxy的Redirect URL与Auth0配置一致性
确认oauth2-proxy的--redirect-url=https://mydomain.ca/oauth2/callback与Auth0控制台的Allowed Callback URLs完全一致,包括HTTPS协议,无拼写错误。
4. 检查HAProxy Ingress认证配置是否生效
查看HAProxy Ingress Controller日志,确认是否转发认证请求到oauth2-proxy:
kubectl logs -n <ingress-controller-namespace> <haproxy-ingress-pod-name>
若日志中无/oauth2/auth相关请求记录,需确认:
- IngressClassName是否正确指向HAProxy Ingress
- 使用的HAProxy Ingress版本支持
haproxy.ingress.kubernetes.io/auth-url注解
5. 验证oauth2-proxy认证日志
查看oauth2-proxy的Pod日志,确认是否处理认证请求:
kubectl logs -n default kafka-ui-oauth2-proxy-<pod-id>
检查日志中是否有用户认证的流程记录,以及是否生成X-Auth-Request-*系列头部。
6. 修正Auth0的Application Login URIs配置
Auth0的Application Login URIs应设置为应用的根地址https://mydomain.ca,而非oauth2-proxy的/oauth2/start路径,确保Auth0能正确识别应用的登录起始地址。
内容的提问来源于stack exchange,提问作者Aniss Chohra

